PT-2008-4462 · Unknown · Rss-Aggregator
Sylvain Thual
·
Publicado
2008-07-07
·
Atualizado
2018-10-11
·
CVE-2008-3033
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RSS-aggregator version 1.0
Description
The issue allows remote attackers to access admin functions without requiring administrative authentication for the admin/fonctions/ directory. This can be exploited through specific requests, such as (1) an IdFlux request to "supprimer flux.php" and (2) a TpsRafraich request to "modifier tps rafraich.php", potentially leading to unspecified other impact.
Recommendations
For RSS-aggregator version 1.0, consider implementing proper authentication mechanisms for the admin/fonctions/ directory to restrict unauthorized access. As a temporary workaround, restrict access to the "supprimer flux.php" and "modifier tps rafraich.php" files until a proper fix is applied.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Rss-Aggregator